Overview
For more than 100 years, BDO Canada LLP (BDO) has grounded its success in strong governance and a steadfast commitment to those we serve. As trusted advisors, we hold ourselves to the highest levels of integrity, quality, and ethical conduct.
Our commitment to ethical practices is central to how we operate. We continuously work to ensure our decisions, behaviours, and systems align with legal obligations, regulatory expectations, and our robust internal governance framework. Upholding our professional duties—whether as auditors, consultants, or strategic partners—remains a core responsibility.
We recognize that our clients place profound trust in us—to safeguard confidential information, uphold our independence, and deliver sound professional services. Our people demonstrate principled leadership by giving back to our communities, protecting our environment, and caring for those less fortunate."
BDO’s governance structure
The BDO Canada LLP Partnership Agreement allows for a maximum of 11 Board members, including up to two independent members to support our commitment to enhancing Board effectiveness and good governance.
As of Dec. 31, 2025, our Board consisted of 11 members, which included:
- Nine partners elected by the partners
- Two external independent members appointed by the Board
In accordance with the BDO Canada Partnership Agreement and applicable policies, the Board exercises oversight of the firm’s business and has established specialized committees to strengthen governance and support the effective execution of its responsibilities. The firm’s Chief Legal Officer acts as Board Secretary and attends all Board and committee meetings as a non-voting member.
Our CEO, Bruno Suppa, is accountable to the Board. In his capacity as CEO, he leads an Executive Leadership Team (ELT) consisting of the Chief Operating Officer (COO) and managing partners who lead the firm across Canada.
The Chief Risk Officer (CRO), Chief Legal Officer (CLO), and Head of Quality and Professional Standards for Assurance have reporting lines to the CEO.
Our Board: 2025 reporting period
As of Dec. 31, 2025, the Board’s composition was made up of the following service lines and members:
- 45% from Assurance
- 18% from Tax
- 18% from outside of BDO (independent members)
- 9% from Advisory
- 9% from Business Services & Outsourcing
| Board member | Office | Service line |
|---|---|---|
| Jameson Bouffard, Chair, Financial Oversight Committee | Toronto, Ont. | Assurance |
| Jameson Bouffard, Chair, Financial Oversight Committee | Toronto, Ont. | Independent Board Member |
| Ryan Brain | Toronto, Ont. | Independent Board Member |
| Mina Farinacci | Montreal, Que. | Business Services & Outsourcing |
| Kelly Hagen | Oakville, Ont. | Advisory |
| Greg London, Chair, Strategy & Execution Committee | St. John’s, N.L. | Tax |
| Daryl Maduke, Chair, Talent & Culture Committee | Vancouver, B.C. | Tax |
| Peter Matutat | Markham, Ont. | Assurance |
| Dan Nagle | Kitchener-Waterloo, Ont. | Assurance |
| David Veld, Board Chair | Oakville, Ont. | Assurance |
| Lorraine Walker | Calgary, Alta. | Assurance |
*As of Dec. 31, 2025
Board skills matrix
Each year, the Board reviews the skills and expertise needed to remain effective in a constantly evolving business landscape. Appendix G highlights the competencies and experience the Board aims to maintain or enhance as part of this ongoing assessment.
These capabilities, which encompass both technical and strategic expertise, support the Board’s effective oversight of BDO’s strategy, risk management and leadership. This table outlines the priority knowledge areas that support the Board in fulfilling its governance responsibilities.
Key competencies and areas of knowledge
- Strategy and business model
- Enterprise risk management (ERM)
- Technology, AI, and digital risk oversight
- Professional services industry knowledge and partnership model insight
- Human capital and talent management
- Financial and accounting acumen
- Board governance and decision effectiveness
- Sustainability, and inclusive leadership
- Regulatory compliance and legal oversight
- Stakeholder engagement and reputation stewardship
- Innovation and strategic change
Board committees
To support the Board in its mandate, it has constituted four sub-committees aimed at addressing critical organizational functions:
- Financial Oversight Committee
- Governance & Risk Committee
- Talent & Culture Committee
- Strategy & Execution Committee
Executive Leadership Team (as of Dec. 31, 2025)
- Bruno Suppa, Chief Executive Officer
- David Simkins, Chief Operating Officer
- Service line leaders
- Jeanny Gu, Managing Partner, Assurance
- Robert Lawrence, Managing Partner, Business Services & Outsourcing
- Rachel Gervais, Managing Partner, Tax
- Jeff Chapman, Managing Partner, Advisory, Markets & Industry Leader
- Strategic Accelerators
- Kerri Plexman, Managing Partner, Talent & Culture
- Sonia Edmonds, Managing Partner, Innovation & Change
Ethical behaviour, and legal and regulatory compliance
Our continued success in the marketplace is rooted in our commitment to quality and the confidence our clients place in us. We work to cultivate a firm-wide culture grounded in integrity and compliance, reinforcing ethical behaviour through ongoing training and adherence to applicable laws, regulations, professional standards, and internal policies.
Every member of BDO is expected to demonstrate the highest standards of honesty, integrity, transparency, and professionalism. Our people are required to follow all relevant legal, regulatory, and professional obligations as they carry out their responsibilities.
How we uphold legal and ethical standards
Our Code of Conduct sets out the ethical standards expected of our people and outlines how we meet our legal, regulatory, and professional obligations, including:
- We manage compliance with regulatory requirements with integrity and in a process-driven manner.
- We protect the confidential and personal data of our clients from unauthorized access, disclosure, and use.
- We maintain a zero-tolerance policy towards any form of bribery, corruption, or other unethical practices.
- We are committed to upholding our policies and procedures against financial crime, corruption, money laundering, drug trading, and human trafficking.
- We adhere to the sanctions imposed by the Canadian government.
- We are committed to fair business practices and competition in all our services.
- We respect our regulators and are committed to work with them to fulfill our role in the public markets.
- Compliance with our Code of Conduct is a condition of partnership and employment within our firm.
In 2025, we introduced the BDO Canada Responsible Artificial Intelligence (AI) policy and issued corresponding mandatory training to reinforce our ethical standards in the use of this emerging technology. The training focuses on professional judgment, data privacy and confidentiality, bias awareness, intellectual property considerations, and compliance with applicable laws, regulations, and professional standards. This initiative supports our commitment to managing emerging risks responsibly while maintaining trust and delivering high-quality professional services. Our AI Governance Committee, chaired by our Chief Risk Officer, is responsible for overseeing the development of AI-related policies, monitoring the evolving AI regulatory and ethical standards, and providing strategic guidance on AI adoption, compliance, and risk mitigation.
To ensure our suppliers share our commitment to ethical and appropriate conduct, we have developed a Supplier Code of Conduct. This Supplier Code of Conduct, which will be rolled out in the future, outlines the standards we will expect from our suppliers. It aligns with our core values and reinforces our dedication to our clients and communities.
Independence
Independence of our firm, partners, and employees is critical to our business and is upheld through comprehensive independence policies, systems, and procedures. These policies and processes are based on independence standards including the Code of Ethics of the IESBA, the Canadian CPA Codes of Professional Conduct, and supplemented as applicable by the independence rules and standards issued and administered by the U.S. Securities and Exchange Commission (SEC) and the Public Company Accounting Oversight Board (PCAOB).
Independence is maintained through the firm’s policies and procedures which include:
- a requirement that all BDO personnel be free from prohibited financial interests and relationships;
- maintenance and communication of restricted entity listings to prevent impermissible financial interests;
- a requirement that assurance engagement team members confirm their independence and, where applicable, consult prior to entering into employment negotiations with an assurance client;
- mandatory partner rotation protocols aligned with professional standards requirements designed to safeguard objectivity and maintain independence;
- annual confirmations of independence and independence training required by all firm personnel;
- mandatory conflict of interest procedures designed to support compliance and confirm that only permissible non-assurance services are being provided to assurance clients and their related entities;
- a centralized business relationship process requiring the Risk Management team’s approval prior to entering into a business relationship with a third party; and
- a requirement that all independence breaches are promptly reported to the Risk Management team upon identification for appropriate evaluation and reporting to the assurance client.
Compliance
Our ethics and independence-first culture are further maintained through compliance with regulatory rules and internal policies and procedures. These processes include annual confirmations of compliance, robust processes for identifying domestic and international conflicts of interest, expert consultation procedures, regulatory compliance monitoring, and confidentiality procedures.
Risk and opportunity oversight
Our approach to managing and identifying risk
Effective risk management is a central pillar of our governance approach and is essential to maintaining the firm’s long-term resilience and performance.
Our Enterprise Risk Management (ERM) program provides a systematic way to identify, assess, and monitor the risks that could influence our ability to achieve our strategic objectives. It also guides how we prioritize significant risks, prepare for emerging issues, and design appropriate mitigation actions.
Grounded in the Committee of Sponsoring Organizations (COSO) framework, the ERM program is led by the Chief Risk Officer and supported by designated Risk Owners and the Executive Leadership Team (ELT), with oversight and direction from the Governance and Risk Committee of the Board.
ERM program objectives
Our objectives for ERM include:
- providing a structured basis for strategic planning and decision-making;
- assisting the firm in achieving its strategic objectives;
- enhancing the firm’s governance and corporate management processes;
- encouraging decision-makers to identify sound business opportunities that will benefit the firm without exposing it to unacceptable levels of risk; and
- providing a practical, usable framework for partners and staff to identify and assess risks inherent in the decisions they take.
Risk identification and assessment
We identify risks and opportunities through several channels, including:
- evaluating our strategy in the context of current and emerging market dynamics;
- reviewing legislative and regulatory developments and assessing their implications for the firm and individual service lines;
- monitoring geopolitical shifts and broader market trends that could influence the professional services landscape and our clients;
- engaging with global and national leadership to understand firm-wide and industry-wide trends; and
- consulting with audit and professional services regulators.
After risks or opportunities are identified, we evaluate them based on their likelihood and potential impact and then assess how well our existing controls or processes address them.
The following risks and opportunities represent those that have the greatest potential to influence our ability to deliver on our strategic priorities should they occur.
Strategic risks and opportunities
- Firm strategy
- Innovation
- IT strategy
Operational risks and opportunities
- Data confidentiality and security
- Cybersecurity
- IT infrastructure
- Market developments and economic uncertainty
- Talent resources
- Engagement processes
- Operational resilience
Regulatory risks and opportunities
- Changes in the regulatory environment
- AI systems
Risk monitoring
With an ever-changing risk landscape, we regularly reassess our risk profile to ensure our ERM program remains responsive and relevant. To support this, we conduct a review of our risk identification and assessment processes twice each year. BDO has begun integrating the identification, assessment, and ongoing monitoring of climate-related risks into our annual risk reviews to ensure responsiveness to both transitional and physical climate risks. Please refer to the Environmental section for further details.
Communication of risk to the Board and ELT
Oversight of the ERM program ultimately rests with the Board, supported by the Governance & Risk Committee. The Risk Management team provides ongoing updates to the Governance & Risk Committee and the Executive Leadership Team, enabling them to monitor key risks, evaluate the effectiveness of controls, and provide strategic direction where needed.
Risk policies and procedures
Beyond the ERM framework, we maintain a suite of risk policies, training programs, and operational procedures designed to promote high-quality service delivery and ensure compliance with professional standards.
These requirements are detailed in our Risk Management Manual, which is accessible to all personnel. The manual outlines key processes such as:
- Quality assurance reviews
- Conflict of interest assessments
- Independence procedures and monitoring
- Client and engagement acceptance protocols
- Risk rating assessments
- Mandatory firm-wide risk training
- Compliance with sanctions obligations
- Compliance with anti–money laundering regulations
International standard on quality management
Regulators in Canada and internationally expect professional services firms to maintain strong, continually improving systems of quality management. In 2020, the Auditing and Assurance Standards Board (AASB) introduced the International Standard on Quality Management 1 (ISQM 1), which was adopted in Canada as CSQM 1. These standards require firms to establish, operate, and regularly evaluate a system of quality management that meets defined objectives and demonstrates operating effectiveness.
BDO continues to align with the requirements of CSQM 1, ensuring that our system of quality management is designed, implemented, and monitored to provide reasonable assurance on operating effectiveness in accordance with the standard so that its objectives are consistently met.
Whistleblower policy
Our whistleblower policy provides a mechanism for individuals at BDO to report concerns that any BDO personnel have engaged in dishonest, unethical, or illegal conduct. The policy explains how concerns can be raised—either through internal reporting channels or anonymously through Mitratech Ethics Hotline (formerly ClearView Connects), an external reporting service that operates confidential whistleblower systems for organizations across Canada. Access to the platform is available to our people through the firm’s intranet.
All members of the firm are expected to understand and follow the requirements of this policy and must complete mandatory training on the whistleblower process and related responsibilities.
Anti-corruption commitment
We are committed to acting ethically in everything we do and preventing corruption in all its forms. The firm’s anti-corruption responsibilities are shaped by Canadian laws and regulations, relevant professional standards, and international requirements that apply when our work spans multiple jurisdictions. To help mitigate corruption risks proactively, we have clear restrictions on certain types of expenditures and maintain a defined policy governing gifts and hospitality. In addition, we follow BDO Global’s anti-bribery and anti-corruption standards, which set consistent expectations for ethical behaviour across the network.
Data protection
Privacy policy
Safeguarding personal information is integral to how BDO operates and for maintaining trust with our clients. We implement a range of technical and organizational measures to meet our privacy commitments, including:
- collecting, using, and disclosing personal information in alignment with our Privacy Statement, internal policies, and applicable legislation;
- implementing safeguards designed to protect personal data from misuse, unauthorized access or disclosure, and accidental loss, destruction, or alteration;
- maintaining processes to address privacy-related questions, concerns, and lawful requests for information; and
- complying with relevant laws and managing potential incidents through established incident response protocols.
To support the confidentiality of client and employee information, we maintain a comprehensive suite of privacy and security policies and procedures.
Data Security and Protection
We are committed to maintaining the confidentiality, integrity, and availability of the information entrusted to us. Information security is fully integrated into our culture, operations, and service delivery, which contributes to our standing as one of the security leaders within the global BDO network.
As custodians of sensitive client and firm data, we have achieved ISO 27001 certification, the global benchmark for information security best practices, positioning the firm as a trusted partner.
Our IT Security team uses a risk-based, continuous-improvement approach to advance our security capabilities. This includes efforts to:
- design and maintain resilient, secure systems;
- prevent unauthorized access to personally identifiable information (PII) and other confidential data;
- ensure external technology partners meet the same security expectations we uphold;
- respond rapidly and effectively to incidents and emerging cyber threats;
- equip our people to play an active role in preventing security incidents; and
- provide clear security assurances to our clients and their clients.
In addition to our firm-wide information security practices, certain engagements require adherence to specific government security requirements. As part of our participation in the Government of Canada’s Contract Security Program, two of our offices successfully re-registered under the program: Winnipeg in 2023 and Ottawa in 2024. Each registration is valid for a three-year term. One Company Security Officer (CSO) and four Alternate CSOs support the protection of sensitive government information and assets, including oversight of secure workplace environments maintained in alignment with federal program requirements.
Aligning governance with evolving challenges
We continually scan shifts in the business, economic, and regulatory environments to understand how new or evolving risks could affect our firm. This forward-looking approach strengthens our governance practices and supports our ability to deliver on the commitments outlined in this report.